Product tour
Everything the system does, on one page. Screenshots of the product, not illustrations.
Regulaxy coordinates maintenance windows on a disconnected network — who is patching what, when, and what might go down with it. This page walks the capabilities in order and shows each one in the screen where it actually happens.
Every screenshot on this page was taken from the running system, against a demo estate. Full detail at the end of the page.
- Outbound calls
- 0Outbound callsNo cloud, no telemetry, no remote licence check.
- Interface languages
- 2Interface languagesHebrew right-to-left and English left-to-right, per user.
- Capability areas
- 12Capability areasInventory, scheduling, collisions, vulnerabilities, compliance and more.
- Bank of Israel directive
- 364Bank of Israel directiveA dedicated module for patch management under §61.4.
The problem
Patching a disconnected estate is a coordination problem, not a technical one.
Installing the update is the easy part. What breaks is everything around it: who approved, who was not told, and what fell over because of something else patched in the same window.
The dependency is in no table
One system talks to another, and nobody sees it until a maintenance window takes both down. The link exists on the network, not in a document.
The inventory belongs to someone else
The real server list lives in tables another team maintains, across several sources that do not always agree with each other.
The evidence is assembled afterwards
When an auditor asks who approved the window and what was checked after it, the answer is reconstructed from a mail thread and people's memory.
What it does
Seven screens covering the full lifecycle.
Each capability gets two lines here: what it solves in business terms, and how it is built. The link opens its full capability page.

The server register, with column filters and sorting.
Information asset register
- Business
- One server list everyone agrees on — with owner, environment, exposure tier and the next date it is due.
- Technical
- Built over three read-only sources another team maintains, reconciled onto a single spine keyed on the full host name. Custom fields are stored alongside and never touch the source tables.

The wizard, on step one of five.
Maintenance window scheduling
- Business
- A five-step wizard that produces a coordinated window: what is being updated, on what, who owns it, when, and who gets told.
- Technical
- The update type decides whether you pick servers, equipment or databases, and the cadence follows exposure — three months for externally reachable hosts, six for internal ones.

Overlapping windows across linked systems.
Collision detection
- Business
- A warning while you are scheduling, when two windows overlap on systems that talk to each other — before the window is committed, not after.
- Technical
- The connection map is built from traffic actually observed, not from a hand-maintained declaration. One collision engine serves the wizard, the collisions page and the alerts.

The monthly operations board, with the risk rail beside it.
The operations board
- Business
- One picture of the month: what is planned, what completed, what failed, and what is about to land on the same evening.
- Technical
- Month, week, quarter and year views over one data source, with a real Outlook invitation per window and an SMS reminder to the owner.

The vulnerability register, in “by patch” mode.
CVE to patch
- Business
- The vulnerability register grouped by the patch that closes them — because what you actually schedule is a patch, not a CVE.
- Technical
- A daily feed from the SOC file drop, matched to hosts authoritatively where a scan result exists and as a stated estimate where it does not. A status set by hand is never overwritten by an import.

Systems ranked, with the score broken down.
Priority scoring
- Business
- What to patch first, by business criticality and how far behind it actually is — with the full reasoning behind every score.
- Technical
- The score is broken into its terms on screen, and the points sum to exactly the score. There is no black box to argue with in a meeting.

A dashboard built by the user.
Dashboards and reports
- Business
- A board each person builds for themselves, and a scheduled report that arrives by mail without anyone exporting anything by hand.
- Technical
- A query builder over the system's own data sources, with drill-through to the underlying rows from any slice. A scheduled report photographs the real board rather than recomputing it.
How it is built
It all runs inside your network. There is no far side.
Regulaxy is installed on a machine inside the disconnected network and speaks only to systems already there. No cloud, no telemetry, and no outbound call to open in a firewall.
- 01Browser — Workstations on the internal network
- 02IIS · URL Rewrite — Reverse proxy on the application server
- 03Next.js — The user interface
- 04FastAPI — Service layer and integrations
- 05MSSQL — Application data, plus read-only inventory sources
- Active Directory — sign-in, contact search and permissions
- Exchange · SMTP — calendar invitations and mail
- The request system — a ticket opened and updated per window
- SMS gateway — a reminder to the owner before the window
- Inventory sources — servers, databases and network equipment
Regulaxy
Application server and database, on your side
- Active Directory — identities and contacts
- Exchange — calendar invites
- SQL Server and Oracle — inventory and databases
- Dynatrace and SolarWinds — topology and equipment
Compliance
Directive 364, not 357.
Proper Conduct of Banking Business Directive 364 consolidated and replaced 357, 361 and 363. Its §61.4 covers patch management — which is exactly what the system records from the moment a window is opened.
Evidence is produced as you go
Who approved, what was performed, what was checked afterwards and what failed — recorded as part of the work, not reconstructed ahead of an audit.
Information asset register
The assets and the links between them, with business criticality and stated ownership for each system.
The נב״ת module
A separate compliance module built on top of Regulaxy, covering the directive's requirements and the mapping of coverage against them.
About the screenshots
Exactly what you just looked at.
Every image on this page is a capture of the running interface — not a mockup and not a rendering. The data inside it is a fully generated demo estate: there is no real server, system or person in any of it.
- The interface
- The product itself
- Captured from the running system
- The data
- A demo estate
- Fully generated, no customer data
- Names and domains
- Fictional
- Including host, system and person names
- Both languages
- The same screen
- Every capture exists in Hebrew and English
There is no customer name, logo, testimonial or outcome metric anywhere on this site. When there is one, it will appear with written consent.
Want to see this against your own estate?
Demos are run with your team, on your scenarios.